Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.38% | — | IBM Sterling Connect Direct WEB Services | 19/1/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system. | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Analizada | Alta (7.5) | 0.51% | — | Restful WEB Services Project Restful WEB Services | 9/1/2025 | 17/6/2026 | Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10. | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Media (5.4) | 0.37% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Crítica (9.8) | 0.55% | — | Apple Smart Card Services | 8/1/2025 | 17/6/2026 | This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp. | |
| Analizada | Media (5.1) | 0.68% | — | Acetech Home Clean Services Management System | 7/1/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /public_html/admin/process.php. The manipulation of the argument type/length/business leads to sql injection. The attack can be… | |
| Aplazada | Alta (7.1) | 0.26% | — | Irshad A Khan Services Updates FOR CustomersAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0. | |
| Modificada | Alta (8.6) | 0.59% | — | Amazon WEB Services Redshift Java Database Connectivity Driver | 24/12/2024 | 17/6/2026 | A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30. | |
| Aplazada | Media (6.5) | 1.3% | 💥 PoC | Wp-base Booking OF Appointments Services AND EventsAI | 21/12/2024 | 17/6/2026 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Alta (8.5) | 0.49% | — | Ydesignservices YDS Support Ticket SystemAI | 18/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YDS Support Ticket System yds-support-ticket-system allows SQL Injection.This issue affects YDS Support Ticket System: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Digital Operation Services WifiburadaAI | 17/12/2024 | 17/6/2026 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5. | |
| Aplazada | Media (4.3) | 0.40% | — | Digital Operation Services WifiburadaAI | 17/12/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5. | |
| Analizada | Alta (7.2) | 23% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | |
| Analizada | Alta (7.2) | 7.7% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 4.9% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access | |
| Aplazada | Alta (7.1) | 0.37% | — | Roninwp FAT Services BookingAI | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Services Booking fat-services-booking allows Stored XSS.This issue affects FAT Services Booking: from n/a through <= 5.6. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Roninwp FAT Services BookingAI | 5/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking.This issue affects FAT Services Booking: from n/a through <= 5.6. | |
| Aplazada | Alta (7.1) | 0.30% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 3/12/2024 | 17/6/2026 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01. | |
| Aplazada | Alta (7.1) | 0.33% | — | Dhrubok Infotech Services LTD Woocommerce Price AlertAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhrubok Infotech Services Ltd. WooCommerce Price Alert price-alert-woocommerce allows Reflected XSS.This issue affects WooCommerce Price Alert: from n/a through <= 1.0.4. | |
| Aplazada | Alta (8.4) | 0.49% | — | B&R Mapp CockpitAIB&R Mapp ViewAIB&R Mapp ServicesAIB&R Mapp MotionAI+1 | 2/12/2024 | 17/6/2026 | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based… | |
| Aplazada | Media (6.5) | 1.2% | — | Keycloak-servicesAI | 25/11/2024 | 21/9/2026 | A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity. |